Security Posture Assessment · Australia

Know where your security really stands.

The SPA gives you a score, the evidence behind it, and the fixes in the order that matters — graded from your real configuration, never a questionnaire.

Start free · no credentials · a real score in two minutes
Covers Microsoft 365, Azure, AWS, Google Cloud and your domain & DNS — assessed against the Essential Eight, ISO 27001, APRA CPS 234 and 40+ more frameworks.

The problem

“So… how secure is your company?”

Almost nobody can answer that with a number, let alone prove it. Here's what we hear instead.

We don't know where we stand.

No score, no baseline, no honest picture of what's actually configured across the business.

We don't know how to find out.

The tooling is scattered, the expertise is expensive, and the answer never seems to arrive.

Another questionnaire.

Forty boxes ticked, a number at the end, and not one line telling anyone what to actually fix.

We failed the audit and did it twice.

Walking in without knowing your posture costs findings, rework, and a second audit fee.

Our edge

The market asks you. We check for you.

Every other free check
You rate yourself.
vs
RG Labs' SPA
We read your real config.

Every free security check in this market is a questionnaire — you rate yourself, a number comes out, and nothing was ever verified. The SPA reads your actual configuration and shows you the exact setting that failed.

The product

Three layers. One report. Start free, go as deep as you need.

Run against your live environment, each layer builds on the last — and you decide where to stop.

01 · Free

External Assessment

Everything an attacker sees before they touch you: email spoofing, DNS, web and TLS hygiene, exposed services. No credentials required.

Free · two minutes
02 · From $800

Cloud Security Control Assessment

Read-only access to M365, Azure, AWS and Google Cloud. 400+ controls graded from live configuration — not from what someone believes is switched on.

Every finding evidenced
03 · From $390/mo

Compliance & Always-On

Your environment graded against the framework you answer to, requirement by requirement — then kept current, so your score and evidence never go stale.

40+ frameworks

Each step is an upgrade, not a restart. Your findings carry forward.

Free external check

Real findings before you spend a dollar.

The free check is a genuine assessment, not a teaser. In two minutes, with nothing shared, it reads the posture the whole internet can already see.

Email authentication

SPF, DKIM and DMARC. Can somebody send mail as you?

DNS integrity

Whether your domain records can be tampered with.

Web & TLS hygiene

HTTPS, HSTS and the headers that stop common attacks.

Exposed services

Ports and services facing the internet that shouldn't be.

Version disclosure

Software versions you're advertising to anyone looking.

Subdomain surface

The forgotten dev, staging and remote-access hosts that widen your attack surface.

A scored result you keep — whether or not you go further.

Inside the report

A number your board understands — and exactly how to fix it.

Every finding shows the literal misconfiguration pulled from the scan, next to RG Labs' analysis and the remediation that closes it.

Sample · NorthLoop Services
68/100
overall posture
4 critical9 high12 medium
Control
Score
Finding
RG Labs analysis
M365-IAM-02MFA on privileged roles
Fail
MFA not enforced3 of 4 Global Admins
Privileged accounts without MFA are the single most exploited path in. Enforce Conditional Access requiring MFA for all admin roles, then remove standing global admin via PIM.
AWS-DAT-01S3 public access
Fail
Bucket world-readableprod-invoices-01
A public bucket holding invoices is a data-breach notification waiting to happen. Enable account-level Block Public Access and scope the bucket policy to the app role only.
EXT-MAIL-02DMARC enforced
Pass
p=reject in place
Spoofed mail failing checks is rejected outright. No action required.

Sample report · a real client's identifiers and remediation redacted for privacy

No other free check in this market can print that middle column.

Compliance

Evidence, not compliance theatre.

Someone is always asking you to prove your security. The SPA turns that question into a document you can hand over the same day.

We assess the technical and cloud controls of these frameworks — the half that can be proven from configuration. The policy, process and people half we'll tell you about honestly, and scope separately. No consultant pretends a scan makes you certified.

The auditor
Show me your Essential Eight maturity.

Scored control by control, with the evidence behind every grade.

The insurer
Complete this renewal form.

Answered from real configuration, not guesses that bite at claim time.

The board
Are we secure?

One posture score they understand, tracked over time.

The customer
Pass our due diligence.

Tender questionnaires answered with proof instead of promises.

CIS BenchmarksISO 27001:2022PCI-DSS 4.0NIST 800-53NIST CSF 2.0MITRE ATT&CKSOC 2HIPAAEssential Eight · engineer-assessedAPRA CPS 234 · AWS, engineer-assessed+40 more on request

Framework availability varies by cloud — CIS and ISO 27001 across all four; PCI-DSS, HIPAA and MITRE on AWS, Azure and GCP; NIST across AWS. We'll confirm exactly what applies to your environment before you buy.

Why RG Labs

Engineers, not a managed service.

Engineer-led

The person who reads your configuration is the one who explains it — and can fix it.

Verified, never assumed

We grade what we can prove and attest the rest. Nothing came from a checkbox.

Fixed scope

You know the price and the deliverable before we start. No open-ended retainers.

No lock-in

We hand the work back documented. Keep us on if it helps, drop us if it doesn't.

You'll know your posture. You'll have the evidence. You'll know what to fix first.

Fixed scope. Fixed price. No lock-in.

Start free. Pay only when you go deeper.

Priced by how many clouds you run, not by the tier. All prices AUD, ex-GST — access unlocks on payment.

Free check — $0A real score and severity breakdown. Instant, no credentials, no obligation.
Run it now →

Rather skip the check and talk to us first? Get in touch →

Domain & Email$800

The full external assessment — every finding with its fix, PDF included.

Start free →
Essentials$1,000

External + 1 cloud (M365, Azure, AWS or GCP).

Start free →
Most commonStandard$1,500

External + up to 2 clouds. The right pick for most Australian mid-market teams.

Start free →
Complete$2,500

External + all 4 clouds (M365, Azure, AWS, GCP).

Start free →
Complete PlusManual assessment & readout$4,500

Everything in Complete, plus engineer attestation of the controls scanners can't see and a live findings & remediation call. Built for regulated and board-driven buyers.

Start free →
MonitoredFrom $390/mo

The report kept live: weekly re-scan, drift alerts and an always-on portal.
2 clouds $390/mo · 4 clouds $590/mo. Annual — 2 months free.

Start free →
Featured service

AI Security Review — prove your AI is safe

Everyone's rolling out AI; almost nobody can prove theirs is secure. We audit your Microsoft 365 Copilot rollout and your AWS & GCP AI services — Bedrock, SageMaker and Gemini — for the oversharing, weak controls and exposed models that quietly leak data. Graded to the AWS AI Security Framework, delivered as its own report. $5,000 standalone · +$2,500 added to a Standard or Complete report

Explore the AI Security Review →

Beyond four environments or multi-entity groups, talk to us.

Start with the free check.

Two minutes, no credentials, a real score at the end. See what the internet can already tell an attacker about you.